1. 18 Nov, 2015 2 commits
  2. 17 Nov, 2015 3 commits
  3. 16 Nov, 2015 2 commits
  4. 11 Nov, 2015 1 commit
  5. 03 Feb, 2017 1 commit
  6. 01 Feb, 2017 3 commits
    • Robbert Krebbers's avatar
      Port to Coq 8.5 beta 2. · 02f213ce
      Robbert Krebbers authored
      The port makes the following notable changes:
      
      * The carrier types of separation algebras and integer environments are no
        longer in Set. Now they have a type at a fixed type level above Set. This
        both works better in 8.5 and makes the formalization more general.
        I have tried putting them at polymorphic type levels, but that increased the
        compilation time by an order of magnitude.
      * I am using a custom f_equal tactic written in Ltac to circumvent bug #4069.
        That bug has been fixed, so this custom tactic can be removed when the next
        beta of 8.5 is out.
      02f213ce
    • Robbert Krebbers's avatar
      Misc prelude omissions. · 462ea92a
      Robbert Krebbers authored
      462ea92a
    • Robbert Krebbers's avatar
      Indexed map function for finite maps. · d101c562
      Robbert Krebbers authored
      d101c562
  7. 10 Jun, 2015 1 commit
  8. 04 Jun, 2015 2 commits
  9. 02 Jun, 2015 1 commit
  10. 21 May, 2015 1 commit
  11. 22 Apr, 2015 1 commit
  12. 16 Apr, 2015 2 commits
  13. 15 Mar, 2015 1 commit
  14. 02 Mar, 2015 1 commit
  15. 25 Feb, 2015 1 commit
  16. 24 Feb, 2015 1 commit
  17. 16 Feb, 2015 3 commits
  18. 13 Feb, 2015 1 commit
  19. 08 Feb, 2015 4 commits
    • Robbert Krebbers's avatar
      Improve case_option_guard to destruct on decide P in case of mguard P. · 6f504682
      Robbert Krebbers authored
      First it would destruct on the decider, which sometimes would result
      in unfolded hypotheses.
      6f504682
    • Robbert Krebbers's avatar
      Improve name generation in the injection' tactic. · 330702cc
      Robbert Krebbers authored
      The tactic "injection' H" now uses the name "H" for the first hypothesis it
      generates. Fresh names will still be used for the remaining hypotheses.
      330702cc
    • Robbert Krebbers's avatar
      Update copyright headers. · 5a73c4ed
      Robbert Krebbers authored
      5a73c4ed
    • Robbert Krebbers's avatar
      Support function pointers and use a state monad in the frontend. · b2109c25
      Robbert Krebbers authored
      Important changes in the core semantics:
      * Types extended with function types. Since function types are a special kind
        of pointer types, types now have an additional mutual part called "ptr_type".
      * Pointers extended with function pointers. Theses are just names that refer
        to an actual function in the function environment.
      * Typing environments extended to assign argument and return types to function
        names. Before we used a separate environment for these, but since the
        argument and return types are already needed to type function pointers, this
        environment would appear in pretty much every typing judgment.
      
      As a side-effect, the frontend has been rewritten entirely. The important
      changes are:
      
      * Type checking of expressions is more involved: there is a special kind of
        expression type corresponding to a function designator.
      * To handle things like block scoped extern function, more state-fullness was
        needed. To prepare for future extensions, the entire frontend now uses a
        state monad.
      b2109c25
  20. 31 Jan, 2015 1 commit
    • Robbert Krebbers's avatar
      Support alignment. · 8b7ea9be
      Robbert Krebbers authored
      Type environments now describe alignment, this allows to:
      * Prove properties about alignment, for example that bit offsets
        of addresses are always aligned.
      * Support align_of expressions in the frontend.
      8b7ea9be
  21. 29 Jan, 2015 2 commits
  22. 27 Jan, 2015 1 commit
    • Robbert Krebbers's avatar
      Let the malloc expression non-deterministically yield NULL. · fdcc90dd
      Robbert Krebbers authored
      * This behavior is "implementation defined" and can be turned on and off
        using the Boolean field "alloc_can_fail" of the class "Env".
      * The expression "EAlloc" is now an r-value of pointer type instead of an
        l-value.
      * The executable semantics for expressions is now non-deterministic. Hence,
        some proofs had to be revised.
      fdcc90dd
  23. 25 Jan, 2015 2 commits
  24. 23 Dec, 2014 1 commit
    • Robbert Krebbers's avatar
      More lenient pointer equality. · 914f32ee
      Robbert Krebbers authored
      Pointer equality is now defined using absolute object offsets. The treatment
      is similar to CompCert:
      
      * Equality of pointers in the same object is defined provided the object has
        not been deallocated.
      * Equality of pointers in different objects is defined provided both pointers
        have not been deallocated and both are strict (i.e. not end-of-array).
      
      Thus, pointer equality is defined for all pointers that are not-end-of-array
      and have not been deallocated. The following examples have defined behavior:
      
        int x, y;
        printf("%d\n", &x == &y);
        int *p = malloc(sizeof(int)), *q = malloc(sizeof(int));
        printf("%d\n", p == q);
        struct S { int a; int b; } s, *r = &s;
        printf("%d\n", &s.a + 1 == &(r->b));
      
      The following not:
      
        int x, y;
        printf("%d\n", &x + 1 == &y);
      914f32ee
  25. 17 Dec, 2014 1 commit